logo

Compromising the Secure Boot Process

ID: 79fb5f98-0e83-550d-9401-2da416b2abc9

STIX ID: report--79fb5f98-0e83-550d-9401-2da416b2abc9

Feed Name: Schneier on Security

Threat Score
75/100

Date Published: 2024-07-26

Date Updated: 2026-04-19

Author: Bruce Schneier

...
...

Researchers discovered that the private platform key underpinning Secure Boot was published (in encrypted form) in a public GitHub repository and was cracked because it was protected by a four-character password; the leaked/test keys were included in production firmware across more than 200 device models from numerous major vendors, effectively compromising Secure Boot as a security guarantee.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.